Bug 2513333 (CVE-2026-68241) - CVE-2026-68241 kernel: drm/i915/mst: limit DP MST ESI service loop
Summary: CVE-2026-68241 kernel: drm/i915/mst: limit DP MST ESI service loop
Keywords:
Status: NEW
Alias: CVE-2026-68241
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-10 12:31 UTC by OSIDB Bzimport
Modified: 2026-08-12 21:48 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-10 12:31:32 UTC
In the Linux kernel, the following vulnerability has been resolved:

drm/i915/mst: limit DP MST ESI service loop

The loop in intel_dp_check_mst_status() keeps servicing interrupts
originating from the sink without bound. Add an upper bound to the new
interrupts occurring during interrupt processing to not get stuck on
potentially stuck sink devices. Use arbitrary 32 tries to clear incoming
interrupts in one go.

Discovered using AI-assisted static analysis confirmed by Intel Product
Security.

Note: The condition likely pre-dates the commit in the Fixes: tag, but
this is about as far back as a backport has any chance of
succeeding. Before that, the retry had a goto.

(cherry picked from commit b4ea5272133059acb493cc36599071a9e852ec2e)


Note You need to log in before you can comment on or make changes to this bug.